Release notes
This page lists changes in each version of Pomme, newest first.
Pomme 0.1.0 (pre-release)
Section titled “Pomme 0.1.0 (pre-release)”Pomme 0.1.0 is a development build. It isn’t published: a v0.1.0 tag and
package publication require green CI, independent review of the Tahoe and
Sequoia live qualification matrices, and a clean disposable-VM qualification.
For details, see Supported macOS versions.
Pomme 0.1.0 begins with an independent history and its own host, control, guest agent, Recovery, packaging, and state identity.
Features
Section titled “Features”- The
pommecommand creates and controls Pomme-owned macOS VMs. Normal macOS runs the persistent, authenticated Pomme guest agent. Bounded Recovery workflows use an expiring, request-bound Pomme Recovery session. Both speak PommeAgentProtocol version 1, and the host helper speaks PommeControlProtocol version 1. pomme mdm VM --profile FILEenrolls a VM in MDM from any state. It creates a missing VM, resumes incomplete creation, finishes a retained standalone SIP or AMFI operation, and then enrolls. You can repeat the command safely after any failure.--dry-runreports the plan without changing the VM.--final-security disabledkeeps the SIP and AMFI changes that enrollment made.- When only the profile’s own certificate payloads validate the MDM server,
Pomme installs them as a separate
com.github.weswhet.pomme.mdm-trust.*configuration profile.
pomme agent update VMreplaces the guest agent in a running VM with the agent from the host’spommebuild. It doesn’t use Recovery or restart the guest. SIP, AMFI, and MDM workflows accept the updated agent. For details, see Update the agent.- Most commands accept
--progress auto|plain|offto control the progress display on standard error.
Command-line syntax
Section titled “Command-line syntax”A command takes at most one kind of positional value: the VM, or the file or endpoint that it acts on. Every other value is a named flag:
- The
pomme jobscommands that act on one job take its ID with--job, and thepomme sessionscommands that act on one session take its ID with--session. For example,pomme jobs logs dev --job JOB_ID. pomme snapshot create,restore, anddeleterequire the snapshot name with--snapshot. For example,pomme snapshot create dev --snapshot clean.pomme shellonly opens a durable shell session, attached or with--detach. It keeps the user, group, working directory, and environment flags, and no longer accepts--timeout,--stdin,--pty,--guest-stdin,--guest-stdout, or--guest-stderr. To run a one-shot shell expression, usepomme exec VM -- /bin/sh -c 'EXPRESSION'.- The
pomme uicommands that act on a VM name it with--vm, which falls back toPOMME_VM_NAME.pomme ui keytakes the key with--key,pomme ui typetakes exactly one of--textor--text-env, andpomme ui key-sequencetakes its keys after--. For example,pomme ui key-sequence --vm dev -- down return. - The unavailable
pomme ui ai settingscommand is removed, andpomme toolsno longer reportsuiCapabilities.settingsAI. - The
pomme toolsandpomme agent-helpJSON output starts atschemaVersion1.
New flags
Section titled “New flags”pomme stop,pomme pause,pomme resume, andpomme deleteaccept--all(-a) in place of VM names. Each acts on the VMs that it applies to:stopon running and paused VMs,pauseon running VMs,resumeon paused VMs, anddeleteon every VM. For details, see Act on every VM.- Every
--forceflag also accepts-f.
Compatibility
Section titled “Compatibility”- The MDM enrollment journal is now schema 6. Pomme reads schema 3–5 journals
with
--final-security restoreand rewrites them as schema 6 on their next update.